Artificial intelligence (AI) is transforming cybersecurity on both sides. Companies are using it to make processes more efficient. At the same time, cybercriminals are using AI to prepare and automate attacks more quickly and make them appear more credible. Yet whilst the threat landscape is becoming more complex due to automated attacks, a dangerous trend is emerging in Switzerland: the priority given to cybersecurity in SMEs is declining. It is time to abandon the ‘head-in-the-sand’ approach and prepare for the inevitable.
Space legend Claude Nicollier once said of the threat from space: “The probability of an asteroid impact is 100 per cent. We don’t know when, but we must be prepared for it.” In today’s digital world, the “impact” is not a chunk of rock, but an encrypted server, a wiped-clean account or a total halt to production. The probability of a cyberattack on a Swiss company is now also close to 100 per cent. The question is not whether it will happen, but when – and whether you are prepared when the digital asteroid strikes.
It is a worrying finding: according to the latest study “SME Cybersecurity 2025”, the issue is losing ground among Swiss SMEs. Whilst everyone is talking about ChatGPT and the next AI revolution, protecting their own infrastructure is slipping down the list of priorities. Many companies are postponing necessary investments in favour of short-term projects.
People are lulled into a false sense of security. “We’re too small”, “There’s nothing to steal from us” or “We’re only connected locally” are phrases we often hear at MTF. Yet it is precisely this complacency that poses the greatest security risk. Cybercriminals no longer operate like snipers who pick out a single, large target. They use AI-driven ‘dragnets’ that continuously scan the internet for vulnerabilities. An SME without an up-to-date security strategy is not a small fish in this net, but easy prey.
The figures speak for themselves: only 42% of Swiss SMEs feel well protected against cyberattacks – down from 55% the previous year. Even more alarming: for 28% of SMEs, cyber security will no longer be a priority by 2025 – an increase from 18% the previous year. This is happening at precisely the moment when the threat landscape is becoming vastly more severe due to AI.
The integration of AI into cybercrime has fundamentally changed the rules of the game. What used to be manual work carried out by hacker groups is now done by algorithms in milliseconds.
AI bots now scan the Swiss internet in real time. They find outdated server software, unsecured remote access points or misconfigured cloud storage faster than a human administrator ever could. As soon as a vulnerability is discovered, the attack is often carried out fully automatically. This means that even if you think your company is “uninteresting”, your infrastructure will become a target simply because of a technical vulnerability.
Thanks to Large Language Models (LLMs), the days of clumsy phishing emails are over. According to the latest figures, 82.6% of all phishing emails are now created with the help of AI. Attackers today generate perfectly worded messages in flawless German (or even Swiss German) that are tailored precisely to the context of your company. These emails are almost indistinguishable from genuine business enquiries. The threshold for clicking on an infected link drops dramatically when the message appears to come directly from a known supplier or your own boss.
We are moving into an era in which we can no longer blindly trust our senses. Deepfakes – audio and video content manipulated or generated by AI – blur the line between reality and deception so perfectly that even experts can barely tell the difference. A brief phone call from a managing director requesting an urgent payment or the release of sensitive data now sounds completely authentic. In a business context, so-called ‘voice cloning’ is particularly dangerous: often, just a few seconds of audio material from public sources such as YouTube videos or interviews are enough to imitate a voice so convincingly that it sounds genuine.
A recent case from the canton of Schwyz illustrates the scale of the problem: an entrepreneur transferred several million francs to an Asian bank account after hearing the AI-cloned voice of his well-known business partner. Schwyz: Criminals make off with millions using artificial intelligence – News – SRF
The statistical trend behind this technology is alarming, as the number of deepfake files detected worldwide has skyrocketed from around 500,000 in 2023 to an estimated 8 million in 2025 – a rise of 1,500 per cent.
The Federal Office for Cyber Security (BACS, formerly NCSC) continues to receive a high volume of reports. In 2025, just under 65,000 reports of cyber incidents were received. That is an average of 177 reports per day – or one report every 8 minutes.
CEO fraud at record levels
Among the fraud offences reported by companies, there has been a marked increase in CEO fraud: 970 cases were reported in 2025 – a 35% increase compared with 2024 (719 cases). Attackers are increasingly using AI-generated content and psychological manipulation to deceive employees.
According to BACS, it is always the same lapses that leave the door wide open:
The good news is: you don’t need to set up your own Security Operations Centre or become an AI expert yourself to protect yourself. It’s all about mastering the basics and consistently implementing modern security strategies.
You can only protect what you know. A professional security assessment is the first step. This involves putting the entire IT infrastructure through its paces: Where is sensitive data stored? Which devices are on the network? Where are the vulnerabilities? MTF helps you achieve this transparency and draw up a list of priorities for securing your systems.
In a world where passwords are cracked in seconds by AI-powered attacks or stolen through sophisticated phishing, MFA is your most important line of defence. It ensures that a stolen password alone is worthless. Despite its enormous protective effect, according to the SME study, only 53% of Swiss businesses consistently rely on MFA – there is an urgent need for action here to effectively prevent identity theft.
Technology alone will never be enough. As attacks are becoming increasingly psychological (social engineering), your staff must be made aware of the risks. Regular training and simulated phishing tests sharpen their awareness of potential threats. A healthy scepticism towards digital instructions should become part of your corporate culture. According to the SME study, only 32% of companies carry out regular security training. Particularly in the case of AI-powered attacks that rely on social engineering, an alert individual is often the last line of defence.
The modern security concept is known as “Zero Trust”. This means that no device or user is trusted by default simply because they are on the company network. Every access attempt must be verified. This prevents an attacker who has gained entry to the system from spreading unhindered throughout the entire network.
Dividing your network into isolated segments acts like fire doors in a building: it prevents threats such as ransomware from spreading like wildfire throughout the entire organisation. In the event of an attack, the damage remains localised, whilst the rest of the infrastructure remains secure and operational. In the age of AI, this is crucial for stopping automated attacks that attempt to spread laterally throughout the entire system in a matter of seconds.
The reality in many SMEs: there is no in-house security department and no 24/7 monitoring. Managed Security Services (MSS) fill this gap. A specialist IT service provider takes charge of continuous monitoring, utilises AI-powered threat detection and responds in the event of an emergency. This gives SMEs access to security expertise and state-of-the-art Security Operations Centres (SOCs) that they could never set up themselves.
When all else fails, your backup is your lifeline. But beware: modern ransomware specifically targets backups in order to encrypt them too. A modern strategy relies on immutable backups, which cannot be tampered with even if the network is successfully attacked.
The threat posed by AI is real – but it is no reason to give up. The comparison with the digital ‘asteroid’ demonstrates one thing above all: preparation is both possible and necessary. The time for excuses is over. In a connected economy, cyber security is no longer just an IT discipline, but a prerequisite for business stability and growth. Those who follow the BACS’s tried-and-tested recommendations, establish clear processes and rely on trustworthy partners can operate with confidence and security even in the age of AI.
Here at MTF, we support Swiss SMEs in bridging the gap between technological innovation and essential security. From risk analysis to contingency planning – we ensure that you are prepared for any emergency.
Let’s build your digital shield together – start with a no-obligation cyber check for your business.